renovate
Holds the self-hosted Renovate configuration and the post-upgrade scripts that keep related dependency pins and lockfiles in sync. The config groups updates into reviewable PRs and limits which helper commands Renovate can run.
moon run renovate:cibunx renovate@44.46.2The ci task typechecks the helpers and tests the config. The Renovate
invocation runs in the renovate job in .github/workflows/renovate.yml, with
tools/renovate/bot-config.json5 selected as its global config.
Credentials
Section titled “Credentials”RENOVATE_APP_CLIENT_ID(GitHub Actions variable) andRENOVATE_APP_PRIVATE_KEY(GitHub Actions secret) authenticate the GitHub App token action. The job uses themainenvironment.- The action mints a per-run installation token. The workflow passes it as
RENOVATE_TOKENto Renovate and asGH_TOKENto the preflight probe. - No persistent Renovate token or credential file is read.
Rotate
Section titled “Rotate”GitHub mints a new installation token for each run; it expires after about one
hour. Infrastructure-as-code in the platform repo stages
RENOVATE_APP_PRIVATE_KEY and RENOVATE_APP_CLIENT_ID. To rotate the key,
a maintainer issues the new value and sets it in the platform repo’s secrets
stack, applies that stack, then applies the stack that stages the GitHub
Actions secrets. Revoke the old key in the App settings only after the
second apply. Nobody edits the Actions secret by hand.